CVE-2025-53528 Information
Jul 22, 2025
cve
Description
Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions 5.4.3 and below the version parameter of the /docs\ endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user’s session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.4.
Reference
https://github.com/zmievsa/cadwyn/commit/b424ecd57cd8dabbc8fe39b8f8ccafea629c7728 https://github.com/zmievsa/cadwyn/security/advisories/GHSA-2gxp-6r36-m97r
Related CNNVD
CNNVD-202507-2813 (Published: 2025-07-21)
Share on: